frstlauncher.exe

FRSTLauncher

forum.viry.cz

The executable frstlauncher.exe, “Tool to run Farbar Recovery Scan Tool” has been detected as malware by 16 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from vyosek.ic.cz.
Publisher:
forum.viry.cz

Product:
FRSTLauncher

Description:
Tool to run Farbar Recovery Scan Tool

Version:
30.09.13.01

MD5:
8bd09b25f2f2b9fae2745ad050ae9e3b

SHA-1:
f16634262dd43354d6ce8f6d7f0c05b693ea523c

SHA-256:
69b9ae0f643170240c6bc10f902942d85305063ced46871e3c15c8bd2b487745

Scanner detections:
16 / 68

Status:
Malware

Analysis date:
1/10/2025 2:10:48 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
DR/Delphi.Gen
7.11.205.178

avast!
Win32:Malware-gen
2014.9-150226

AVG
Dropper.Agent
2016.0.3187

Clam AntiVirus
Trojan.Agent-171150
0.98/21511

Comodo Security
Backdoor.Win32.PcClient.~dy002
20874

Fortinet FortiGate
BackDoor.WD!tr
2/26/2015

F-Prot
W32/Trojan2.HJCD
v6.4.7.1.166

G Data
Win32.Trojan.Agent.0WDTMM
15.2.25

IKARUS anti.virus
Backdoor.Win32.PcClient
t3scan.1.8.6.0

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.2428

McAfee
Artemis!8BD09B25F2F2
5600.6843

NANO AntiVirus
Trojan.Win32.Agent.bjsap
0.30.0.65070

Norman
Suspicious_Gen4.GQOCM
11.20150226

Qihoo 360 Security
Win32/Trojan.Multi.daf
1.0.0.1015

Sophos
Mal/Generic-S
4.98

VIPRE Antivirus
Trojan.Win32.Generic
37040

File size:
110 KB (112,640 bytes)

Product version:
25.11.13.01

Copyright:
Tempest&vyosek&team

Trademarks:
forum.viry.cz

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.25

CTPH (ssdeep):
3072:TJoQcYqu/3PAp7dBq4O9y77DoEjbZ6/NzT:TJAYq83wdc4O9uBHA9

Entry address:
0xC7D0

Entry point:
55, 8B, EC, B9, 09, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, A1, 04, D4, 40, 00, C6, 00, 01, B8, 58, C7, 40, 00, E8, B0, 81, FF, FF, 33, C0, 55, 68, EB, CD, 40, 00, 64, FF, 30, 64, 89, 20, A1, D0, D2, 40, 00, 33, D2, 89, 10, 8D, 45, E8, E8, E1, E5, FF, FF, 8B, 55, E8, B8, 94, F8, 40, 00, E8, 40, 72, FF, FF, B8, 98, F8, 40, 00, BA, 00, 08, 00, 00, E8, 51, 76, FF, FF, 68, 00, 08, 00, 00, A1, 98, F8, 40, 00, E8, AA, 75, FF, FF, 50, A1, 94, F8, 40, 00, E8, 9F, 75, FF, FF, 50, E8, B9, 82, FF, FF, BA...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
48 KB (49,152 bytes)

The file frstlauncher.exe has been seen being distributed by the following URL.

Remove frstlauncher.exe - Powered by Reason Core Security